Trojan.Aotera.G
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 11,768 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 20 |
| First Seen: | March 25, 2026 |
| Last Seen: | July 29, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Aotera.G on your system indicates a potential security threat that requires immediate attention. This type of threat is generally categorized as a Trojan, which is a broad term for malicious software that disguises itself as legitimate. Trojans can have various functions, including data theft, unauthorized access, and disruption of system operations. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.
Table of Contents
What Is Trojan.Aotera.G?
Trojan.Aotera.G is identified as a Trojan-type threat, which means it is designed to infiltrate your system by disguising itself as a legitimate program or file. The name itself does not directly indicate a specific malware family, but rather serves as a detection label. Trojans are known for their versatility and can be used for a wide range of malicious activities, including but not limited to, stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system.
How Trojan.Aotera.G Operates
Like other Trojans, Trojan.Aotera.G is likely designed to operate stealthily, attempting to evade detection by security software. It may exploit vulnerabilities in operating systems, applications, or user behavior to gain access to the system. Once inside, it can perform various malicious actions, depending on its specific design and purpose. This could include communicating with command and control servers, downloading additional malware, or capturing and transmitting sensitive user data.
Symptoms of Infection
Symptoms of a Trojan infection can vary widely, depending on the specific goals of the malware. Common indicators include unexpected system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons. You might also notice unusual network activity, changes to system settings, or the appearance of unwanted pop-ups and advertisements. In some cases, the infection may not exhibit obvious symptoms, making it difficult to detect without the aid of security software.
How to Remove Trojan.Aotera.G
- Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary tools while restricting the operation of most malware.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to enhance detection capabilities.
- Uninstall suspicious programs that you do not recognize or that were installed around the time the infection was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
- After completing the above steps, reboot your system and perform another full scan to ensure the malware has been successfully removed. Repeat the scanning process until no threats are detected.
Conclusion
Removing Trojan.Aotera.G requires a systematic approach to ensure all components of the malware are eliminated from your system. By following the steps outlined above and maintaining vigilant security practices, you can protect your system from future infections. Regularly updating your operating system, applications, and security software, along with being cautious when opening emails or downloading files from the internet, are crucial steps in preventing malware infections. Remember, the key to securing your digital environment is a combination of robust security tools and informed user behavior.
Analysis Report
General information
| Family Name: | Trojan.Aotera.G |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
540b837bd5753be65f2ac67d33887d2e
SHA1:
235453e5e165241e9cb47c846e664cb222e78fe1
SHA256:
719ADFFEA102C9AE79433D003A7F0C806B3273D9137369F0A8E952925DD49889
File Size:
2.48 MB, 2478592 bytes
|
|
MD5:
5eacc7becae19c2e319f0cd3e22db76e
SHA1:
202acee4eae4f662e28ac9bd06d04ed4b5204f0d
SHA256:
02BD3F91A93F25EBAA9637EA6949F555B7CDC47A216F051CD2B24612540B792C
File Size:
2.13 MB, 2134016 bytes
|
|
MD5:
47e4ac5246b57d0b4c792a16224ef1ef
SHA1:
e1753b6d4e21c38e1618bf2928cf0cd01af120a0
SHA256:
0C12A02D00900E8429083881F181548420DFE2DC9041C477B636CDDCFB3EAA71
File Size:
2.29 MB, 2286592 bytes
|
|
MD5:
316a635078339ef88da27e0c792f0d53
SHA1:
95e8f495ebf328d204c047b45388eba6c962950a
SHA256:
2C51455A5A584989C89A2C7ED859C8861C3F89F88B64909AD39A7D7BB806DB55
File Size:
2.72 MB, 2724864 bytes
|
|
MD5:
ad4e33e8d485c7b9a157fac984457fbb
SHA1:
52cf7414770b20fd0db440934d4cc6db98425423
SHA256:
35E1F0757436C0E2EF201479F8AA2032E591B0E34441A270E7A2CC2D1290805D
File Size:
2.03 MB, 2027008 bytes
|
Show More
|
MD5:
16232beda86f91212826a302ac9f07b6
SHA1:
da66324006f22dd7b866f50d388991c769ee7127
SHA256:
D97BCA46AA5F61D73172D3C9651AC96EB0BD0BD768FFF8170A9365863F1C1B6E
File Size:
2.66 MB, 2660352 bytes
|
|
MD5:
e0ba3c5742b0586b50ad41dcc4c83e45
SHA1:
1a982ff9c0f73144281a71980039128b67c0b7f1
SHA256:
302C894F774A377CFF0D0863E517665A3D2C4D7A3DF1500B5551982B03816A08
File Size:
6.50 MB, 6496768 bytes
|
|
MD5:
c53f34fa5416d27d7a4c67895f3f2f53
SHA1:
819a6efd9e61a98c89e7b91a077b5c74af71b66e
SHA256:
C1D935AC5715BFF4FC19835B3D06378CF2A14776507647C398B2D2FDFF2D3A8C
File Size:
3.31 MB, 3311104 bytes
|
|
MD5:
502b99f4630e01f4ad315228e00e3738
SHA1:
9ad0c8e3156947af0b3618ce9a73bee04cf7b74b
SHA256:
5582F2086BEAA666F9A520634C4AE7EC46E4FFC01A54F196B6CE8CBABC126479
File Size:
1.84 MB, 1841152 bytes
|
|
MD5:
fbb8ec00c09fb6b27927d5012c556490
SHA1:
a695f5cecad90808018bc7869ae5467ba1b4a49a
SHA256:
C6C52E3F9FEA0C977AF1A5FFDF717690A489E167EC6515315B92DD558A114491
File Size:
1.92 MB, 1918464 bytes
|
|
MD5:
97987f0485fd47bb07f1bc082564123f
SHA1:
60ae01afe8c28b3b2c66b5da07b99b0d520ff1d0
SHA256:
1BFC8230E6E1AE0E4F3EB00D46D1F2FF3806E66CCE2400978A08E484AC20C220
File Size:
1.90 MB, 1901568 bytes
|
|
MD5:
dc5859aa3e12e2bd3e04f1b9d4142abb
SHA1:
d451fd0b6b9cdf481a5867ddcfcccfbe8a0739a8
SHA256:
38E74FF8D5F02617FF8858D9094B455D4E999223C7F78726584690E7201D94B7
File Size:
2.71 MB, 2709504 bytes
|
|
MD5:
1bc37fbb51b6ba71f27b3df8db32fe63
SHA1:
7b65696ef754dff1538e66e8878acdf5aff042a0
SHA256:
09FF776AE819EF8AE7E0CB0CCE49D8C7608B7EEC4D4A75DD58C8376392396356
File Size:
4.04 MB, 4040704 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- 2+ executable sections
- dll
- fptable
- HighEntropy
- VirtualAllocExNuma
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 6,999 |
|---|---|
| Potentially Malicious Blocks: | 141 |
| Whitelisted Blocks: | 6,853 |
| Unknown Blocks: | 5 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.DFCF
- Agent.DFCI
- Agent.DFCJ
- Agent.DFD
- Agent.DFZ
Show More
- Agent.KOK
- Aotera.A
- Aotera.D
- Aotera.E
- Aotera.G
- Aotera.LA
- Filecoder.XT
- Kryptik.OID
- Kryptik.OIF
- Kryptik.PSB
- Kryptik.VED
- Kryptik.YKAC
- Kryptik.YKAP
- Kryptik.YKBB
- Mikey.UB
- Mikey.UC
- Mikey.W
- ShellCode.FJ
- SnakeStealer.A
- Trojan.Filecoder.Gen.AF
- Trojan.Filecoder.Gen.BI
- Trojan.Filecoder.Gen.BP
- Trojan.Metasploit.Gen.AT
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n . �v���5Bx #��(�1�1HO 1�D9ߔ@V� H[uR20_�z`�2b"hi��k�ql(�rnJ u�~ {b�{�=�P� ������ ������T��T���.�T��T��T��m� Ù� �gi�� ����$�>წ�����(��o A��=�SB1_ B�� T�Vw�`�V�R� ��%�� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n ' |